Description
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution and System Takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Siebel Management Console component of Oracle Siebel CRM Deployment and is an improper access control flaw (CWE-284). A high‑privileged attacker who has network access through HTTP can exploit the flaw to take full control of the deployed system, compromising confidentiality, integrity, and availability. Successful exploitation leads to a complete system takeover, with the potential to affect other integrated products within the deployment due to the scope change indicated by the vulnerability.

Affected Systems

Oracle Corporation’s Siebel CRM Deployment is affected in all versions from 17.0 through 26.7. The vulnerability resides in the Management Console and is applicable only to deployments of the Siebel CRM product that use these version ranges.

Risk and Exploitability

The CVSS v3.1 base score of 9.1 indicates critical severity. With an EPSS score of less than 1%, exploitation is considered unlikely but still possible, particularly to highly privileged attackers. The vulnerability is not listed in the CISA KEV catalog. An attacker can target the exposed HTTP interface of the Siebel Management Console, gaining privileged access and potentially impacting additional products that are part of the same deployment environment.

Generated by OpenCVE AI on September 18, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade Siebel CRM Deployment to a version that has fixed this vulnerability.
  • Restrict HTTP/HTTPS access to the Siebel Management Console so that only trusted internal IPs or VPN users can reach it.
  • Review and tighten access controls, ensuring that only authorized high‑privilege accounts can log into the Management Console.
  • Monitor logs for suspicious authentication or session activity to detect early signs of exploitation.

Generated by OpenCVE AI on September 18, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Siebel Management Console Remote Takeover via HTTP

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Siebel Management Console Remote Takeover via HTTP
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle siebel Crm Deployment
CPEs cpe:2.3:a:oracle:siebel_crm_deployment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle siebel Crm Deployment
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Siebel Crm Deployment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:13:23.115Z

Reserved: 2026-08-31T15:40:57.347Z

Link: CVE-2026-83229

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:13.925Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:34.743

Modified: 2026-09-17T16:18:10.660

Link: CVE-2026-83229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:45:13Z

Weaknesses